CVE-2006-2449: Medium severity KDE kde vulnerability
Published Jun 15, 2006
·Updated
KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.
Affected Software
14 affected components
KDE kde=3.3.2
KDE kde=3.3.1
KDE kde=3.2.2
KDE kde=3.2.1
KDE kde=3.4.3
KDE kde=3.5.2
KDE kde=3.4
KDE kde=3.5
KDE kde=3.5.3
KDE kde=3.3
KDE kde=3.2
KDE kde=3.2.3
KDE kde=3.4.2
KDE kde=3.4.1
Remediation
Patch Available
Event History
Jun 15, 2006
CVE Published
10:02 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2449?
CVE-2006-2449 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2006-2449?
To fix CVE-2006-2449, upgrade to a patched version of KDE that addresses the symlink attack issue.
3
What versions of KDE are affected by CVE-2006-2449?
CVE-2006-2449 affects KDE versions from 3.2.0 up to 3.5.3.
4
What type of attack is described in CVE-2006-2449?
CVE-2006-2449 describes a symlink attack that allows local users to read arbitrary files.
5
Who can exploit CVE-2006-2449?
CVE-2006-2449 can be exploited by local users with access to the system.